ChainBleedv0.1 · open intel
← back to feed·EXTERNAL-CALL2022-11-10 · 3y ago
Incident · SLOWMIST

brahTOPG

Contract Vulnerability
Estimated loss
$89.9K
VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
▰ METHOD
EXTERNAL CALL
EXTERNAL-CALLBYTECODE CATCHABLEAI SCANNABLE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

▰ PROOF OF CONCEPT
DEFIHACKLABS
src/test/2022-11/BrahTOPG_exp.sol
view forked test on github ↗

Reproducible Foundry test fork from SunWeb3Sec/DeFiHackLabs. Clone the repo, run forge test against the file path above, and replay the exploit against a mainnet fork at the historical block. Use for reproduction only — not for live targets.

Forensic narrative

According to the monitoring of the SlowMist security team, the brahTOPG project on the ETH chain was attacked, and the attacker made a profit of about $89,879. The main reason for this attack is that the Zapper contract strictly checks the data passed in by the user, which leads to the problem of arbitrary external calls. The attacker uses this arbitrary external call problem to steal the tokens of users who are still authorized to the contract. Attack method (per SlowMist): Contract Vulnerability. Reported loss: $ 89,879.

Primary source
https://twitter.com/SlowMist_Team/status/1590685173477101570
Sourced from
slowmist
Technical record
chain
protocol
brahTOPG
bug_class
external-call
date_occurred
2022-11-10
loss_usd
$89,879
source_id
sm:brahtopg::2022-11-10
Related — same bug class· external-call
2026-04-27
1mo ago
ZetaChain
Contract Vulnerability
external-call
$334.0K
UNRATED
2026-01-26
4mo ago
ETH
SwapNet
Contract Vulnerability
external-call
$16.80M
UNRATED
2026-01-06
5mo ago
ETH
Fusion by IPOR
Contract Vulnerability
external-call
$336.0K
UNRATED
2025-09-27
8mo ago
Hyperdrive
Contract Vulnerability
external-call
$782.0K
UNRATED
2024-08-28
1y ago
Aave
Contract Vulnerability
external-call
$56.0K
UNRATED
2024-07-23
1y ago
Spectra
Contract Vulnerability
external-call
$550.0K
UNRATED
ChainBleed — live web3 threat intelligence